Impact
In versions of Flatpak prior to 1.18.1 a malicious sandboxed application can replace the user‑specific ld.so file with a symlink. During regenerate_ld_cache this symlink causes the cache regeneration process to write a file to an attacker‑controlled location inside the user’s home directory, leading to arbitrary file overwrite. While the attacker cannot control the name or contents of the written file, the overwrite can modify or delete critical user files, potentially allowing privilege escalation or data tampering.
Affected Systems
The vulnerability affects all Flatpak releases before 1.18.1. Flatpak users running the default 1.18.0 or older, including those on distributions where the 1.18.1 update has not been applied, are at risk. Backported fixes are available for LTS distributions in the flatpak‑1.16.x branch, requiring the cherry‑picked glnx changes to be present.
Risk and Exploitability
The CVSS score of 4 indicates moderate severity, and there is no current EPSS data or KEV listing. The attack vector requires the presence of a sandboxed application already executed with user privileges, making it a local privilege escalation scenario rather than a remote attack. Because the attacker cannot control the file name or content, exploitation complexity is lower, but the impact remains significant for the affected user environment.
OpenCVE Enrichment